The domain passkeys are bound to

A passkey is tied to one domain and its subdomains, and that binding is what makes it impossible to phish. Blank means the module derives it from your app address. Set it deliberately if you might move the app later: a passkey created for portal.example.com will not work on app.example.com, but one created for example.com works on both. Changing this setting does not migrate anything. Every existing passkey stops working and everyone has to enrol again, so decide before people start enrolling rather than after.